PatchSiren

rConfig CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM rConfig CVE published 2026-07-20

CVE-2026-63102

CVE-2026-63102 is a medium-severity privilege escalation vulnerability in rConfig Core before 8.2.8. The vulnerability allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest [truncated]

Known exploited rConfig CVE published 2021-11-03

CVE-2020-10221

CVE-2020-10221 is an OS command injection vulnerability in rConfig. CISA lists it in the Known Exploited Vulnerabilities (KEV) catalog, which means there is evidence of active exploitation and the issue should be treated as a defensive priority. The supplied corpus does not include affected version details or a vendor advisory, so remediation should follow vendor update guidance and be paired with exposur [truncated]